US11790057B2ActiveUtilityA1

Controlling program execution using an access key

Assignee: SAP SEPriority: Aug 17, 2021Filed: Aug 17, 2021Granted: Oct 17, 2023
Est. expiryAug 17, 2041(~15.1 yrs left)· nominal 20-yr term from priority
Inventors:Gernot Sachs
G06F 21/121H04L 9/0825H04L 9/302H04L 9/3247G06F 8/60G06F 21/1063H04L 9/0643G06F 21/107
34
PatentIndex Score
0
Cited by
14
References
20
Claims

Abstract

Systems, methods, and computer-readable media for controlling the execution of a deployed software program to a customer system are disclosed herein. A vendor may deploy a software program to the customer system. The software program may comprise an access key, the access key comprising a digital signature and access parameters. The digital signature may utilize a public key private key pair. The customer may run the software program by validating the access key on the customer system. Validating the access key may comprise verifying the digital signature and verifying the access parameters. Once the access key has been validated, the customer may execute the software program on the customer system.

Claims

exact text as granted — not AI-modified
Having thus described various embodiments of the invention, what is claimed as new and desired to be protected by Letters Patent includes the following: 
     
       1. A method comprising:
 deploying, from a vendor system to a customer system, a first computer program; 
 receiving, from the customer system, an indication of an inconsistency in a data table encountered during execution of the first computer program; 
 accessing a second computer program designed to fix the inconsistency; 
 defining at least one vendor access parameter for the second computer program; 
 deploying from the vendor system to the customer system, the second computer program; 
 receiving, from a customer at the customer system, an access key requesting access to execute the second computer program, 
 wherein the access key comprises a digital signature and at least one customer access parameter; 
 validating, at the customer system, the digital signature using a public key private key pair, 
 wherein the private key of the public key private key pair is known by the vendor system as corresponding to one or more vendor-approved users having requisite knowledge to correctly execute the second program to fix the inconsistency; 
 verifying that the at least one customer access parameter matches the at least one vendor access parameter; and 
 in response to the verifying, causing execution of the second computer program on the customer system. 
 
     
     
       2. The method of  claim 1 , wherein the at least one vendor access parameter comprises a user identification. 
     
     
       3. The method of  claim 1 , wherein the at least one vendor access parameter comprises a validity time parameter indicative of an amount of time the access key is valid. 
     
     
       4. The method of  claim 1 , wherein the method further comprises generating the public key private key pair using a Rivest-Shamir-Adleman% RSA) algorithm. 
     
     
       5. The method of  claim 1 , wherein the method further comprises delivering, from the vendor system to the customer system, the public key of the public key private key pair. 
     
     
       6. The method of  claim 1 , wherein the second computer program is a specialized computer program developed to correct a data inconsistency within the customer system. 
     
     
       7. The method of  claim 1 , wherein the at least one customer access parameter is verified at a runtime associated with the second computer program. 
     
     
       8. One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by a processor, perform a method comprising:
 deploying, from a vendor system to a customer system, a first computer program; 
 receiving, from the customer system, an indication of an inconsistency in a data table encountered during execution of the first computer program; 
 accessing a second computer program designed to fix the inconsistency; 
 defining at least one vendor access parameter for the second computer program; 
 deploying from the vendor system to the customer system, the second computer program; 
 receiving, from a customer at the customer system, an access key requesting access to execute the second computer program, 
 wherein the access key comprises a digital signature and at least one customer access parameter; 
 validating, at the customer system, the digital signature using a public key private key pair, 
 wherein the private key of the public key private key pair is known by the vendor system as corresponding to one or more vendor-approved users having requisite knowledge to correctly execute the second program to fix the inconsistency; 
 verifying that the at least one customer access parameter matches the at least one vendor access parameter; and 
 in response to the verifying, causing execution of the second computer program on the customer system. 
 
     
     
       9. The media of  claim 8 , wherein the access key is configured to control the execution of a portion of the second computer program. 
     
     
       10. The media of  claim 8 , wherein the at least one access parameter comprises a runtime parameter indicative of a number of times the second computer program can be executed. 
     
     
       11. The media of  claim 8 , wherein the method further comprises generating the digital signature using a public key infrastructure. 
     
     
       12. The media of  claim 8 , wherein the method further comprises storing the at least one access parameter in a data store. 
     
     
       13. The media of  claim 8 , wherein the at least one access parameter is a client identification parameter validating a client associated with the customer system. 
     
     
       14. The media of  claim 8 , wherein the method further comprises in response to receiving the access key, generating a time stamp for the access key. 
     
     
       15. A system for controlling execution of a computer program deployed on a customer system, comprising:
 a data store; 
 a processor; and 
 one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the processor, perform a method comprising: 
 deploying, from a vendor system to a customer system, a first computer program; 
 receiving, from the customer system, an indication of an inconsistency in a data table encountered during execution of the first computer program; 
 accessing a second computer program designed to fix the inconsistency; 
 defining at least one vendor access parameter for the second computer program; 
 deploying from the vendor system to the customer system, the second computer program; 
 receiving, from a customer at the customer system, an access key requesting access to execute the second computer program, 
 wherein the access key comprises a digital signature and at least one customer access parameter; 
 validating, at the customer system, the digital signature using a public key private key pair, 
 wherein the private key of the public key private key pair is known by the vendor system as corresponding to one or more vendor-approved users having requisite knowledge to correctly execute the second program to fix the inconsistency; 
 verifying that the at least one customer access parameter matches the at least one vendor access parameter; and 
 in response to the verifying, causing execution of the second computer program on the customer system. 
 
     
     
       16. The system of  claim 15 , wherein the at least one vendor access parameter comprises at least one of an installation identification and a software identification to validate the second computer program is compatible with the customer system. 
     
     
       17. The system of  claim 15 , wherein the second computer program is a specialized correction program configured to correct a bug within the customer system. 
     
     
       18. The system of  claim 17 , wherein the at least one vendor access parameter comprises a program identification parameter allowing the second computer program to correct the bug across a plurality of computer programs within the customer system. 
     
     
       19. The system of  claim 18 , wherein the method further comprises encrypting the at least one vendor access parameter to create the digital signature. 
     
     
       20. The system of  claim 19 , wherein the digital signature is created at the vendor system.

Join the waitlist — get patent alerts

Track US11790057B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.